← Custodia
CMMC Level 1 · Engineering services

CMMC Level 1 for engineering services firms

Engineering services firms providing studies, design, analysis, and technical support to federal agencies often start at CMMC Level 1. Contract documents, deliverables, schedules, and correspondence are Federal Contract Information (FCI). Because engineering deliverables and reference data are frequently marked Controlled Unclassified Information, scoping is critical: marked CUI moves that work to Level 2.

Overview

If your firm provides engineering studies, design, analysis, testing support, or technical services to federal agencies, your task orders, deliverables, schedules, and program correspondence are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation.

Engineering is one of the services where CUI shows up most often, because design data, drawings, specifications, and reference material on defense systems are frequently marked. When the agency or prime gives you marked CUI to work with, or flows down DFARS 252.204-7012 and sends marked data, that work is Level 2 and needs a controlled environment.

The right move is disciplined scoping per engagement. Plenty of engineering support work involves only FCI and sits at Level 1. The engagements that involve marked technical data are Level 2 and belong in a separate, documented enclave.

Typical contracts you'll see

  • Engineering studies, analyses, and design support task orders
  • Technical and engineering support services for program offices
  • Test, evaluation, and surveying support contracts
  • Subcontracts under an engineering or A and E prime
  • SBIR and STTR Phase I engineering prototypes

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Task orders, modifications, and invoices
Engineering deliverables and reports that are not marked CUI
Project schedules, status reports, and meeting minutes
Unmarked drawings, models, and analysis files produced under the contract
Correspondence with the contracting officer and program office

Common pitfalls in this industry

  • Assuming all engineering work is Level 2, when plenty of support work is FCI only and sits at Level 1.
  • Missing marked CUI in a deliverable package and continuing to run at Level 1, when that work is Level 2.
  • Sharing CAD and analysis files on an open network drive, which fails FAR 52.204-21 (b)(1)(iii).
  • Letting engineers use personal, unencrypted laptops with no MFA for federal work.
  • Publishing technical approaches or program details before the agency clears them, which fails (b)(1)(iv).
  • Treating the SPRS affirmation as a one time task instead of an annual obligation.

Your Level 1 action plan

  1. 01Scope each engagement: FCI only or marked CUI involved. Confirm in writing with the agency or prime.
  2. 02Keep FCI only engagements at Level 1 and stand up a controlled enclave for any engagement with marked CUI.
  3. 03Move federal engineering work onto a paid Microsoft 365 or Google Workspace tenant with MFA enforced.
  4. 04Set CAD, model, and analysis file access to least privilege per project, and give each engineer a named account.
  5. 05Encrypt every laptop and workstation used for federal work and protect remote access with MFA.
  6. 06Write a one to two page boundary description: which systems hold federal FCI and how marked CUI work is kept separate.
  7. 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 541330Engineering Services
  • 541380Testing Laboratories
  • 541370Surveying & Mapping (except Geophysical) Services
  • 541360Geophysical Surveying & Mapping Services
  • 541715R&D in the Physical, Engineering & Life Sciences

Frequently asked questions

Q.Is engineering support always Level 2 because of technical data?

No. Engineering work is Level 1 when it involves only Federal Contract Information. It becomes Level 2 when the agency or prime gives you marked CUI to work with, or flows down DFARS 252.204-7012 with marked technical data. Many engineering support engagements involve only FCI and stay at Level 1, while specific technical data programs are Level 2.

Q.How do I know if a drawing or spec is CUI?

CUI is explicitly marked. Look for a CUI banner and category markings such as Controlled Technical Information or Export Controlled. Unmarked drawings and specifications produced or received under the contract are FCI. If something should be marked but is not, ask the contracting officer rather than guessing.

Q.Can I keep most of my firm at Level 1 if one contract has CUI?

Yes. Scope the CUI contract into a separate, controlled environment and keep the rest of the firm at Level 1. Document the boundary clearly so a reviewer can see which systems hold CUI and which hold only FCI. Many engineering firms run exactly this split.

Q.Do I need an SSP for the Level 1 part of my work?

No. Level 1 does not require a System Security Plan under 32 CFR Part 170. The Level 2 work does require an SSP and a NIST SP 800-171 assessment. For the Level 1 part you need evidence the 15 practices are met, a short boundary description, and a current list of authorized users.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
IT services & managed service providers (MSPs)
Read the it services & msps guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Management & professional services consultants
Read the professional consulting guide →
Staffing & workforce services firms
Read the staffing services guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Industrial machinery & equipment suppliers
Read the industrial equipment guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Medical device & instrument manufacturers
Read the medical devices guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Research, development & testing labs
Read the research & development guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)